5 ms·
I love this level of transparency.
by misterpigs 3y ago
I love this level of transparency.
- voynich 3y agoYeah, whether necessary or not, it's still nice to have such a level of detail in a transparency report.
- tomjen3 3y ago> We will not be releasing the usernames involved publicly or to the users themselves. Which is the most important part.
- tptacek 3y agoThey're not allowed to release that. Edit I read 'chaps as saying there was an NDA on the subpoena, but apparently there wasn't, so this might just be flatly wrong.
- AnotherGoodName 3y agoThe NDA isn't the only reason you don't risk interference in an ongoing investigation though so regardless the basic point still stands.
- remram 3y agoEven in the absence of NDA, are you allowed to? Counsel has apparently advised them not to. Would it not carry the risk of being complicit to a crime?
- kevin_thibedeau 3y agoDisclosing facts is not a crime.
- remram 3y agoThere are lots of situations in which disclosing facts is indeed a crime. You are answering my specific question with a nice sounding maxim which is obviously not true in general.
- rocqua 3y agoPerhaps there is no NDA on the fact that subpoenas were issued, but still an NDA on whom they were issued about? Limiting The scope of such an NDA feels like a plausible result of negotiations after a motion to squash the subpoena.
- dev_tty01 3y agoReleasing the user names would not be respecting the privacy of the users.
- SV_BubbleTime 3y agoSure. But I would love if they had considered this from the start: >As a result we are currently developing new data retention and disclosure policies. “I guess we don’t actually need that” should have been the idea from the start.
- thih9 3y agoAfter a quick glance at the information listed in the report I didn't notice excessive data collection on pypi's part. I'd say they followed "I guess we don't actually need that" approach reasonably well so far and good for them if they want to improve that even more.
- donaldstufft 3y agoOne important thing to remember here is that PyPI was originally started in 2002 as a weekend hack project that grew overtime to become the piece of critical infrastructure it is today. There's a lot of stuff in PyPI that exists as historical baggage and cruft and reviewing them just never bubbled up to be a priority. Likewise a lot of the policies it has have been added and grown overtime as something happened that caused us to need one. On top of all of that, it's volunteer run and has been understaffed for basically it's entire life, so sitting down and figuring out a proper data retention policy that takes a holistic view of everything we have just never bubbled up. In general I think we already do a pretty good job of collecting a minimal amount of data, and hopefully with proper policies we can do an even better job.
- throwaway_13140 3y agoDo you still love it if it enables a terrorist or otherwise very bad person to evade capture?
- evandale 3y agoNot OP but yeah. I don't buy into the whole "to protect you from bad people I need to erode your rights" argument. Never made sense to me. Terrorists and other very bad people usually aren't in the business of following laws so I don't know what crimes you'd prevent by weakening the rights of everyone else.
- M3L0NM4N 3y agoI mean, surveillance reduces crime. Wherever you fall on the spectrum of surveillance/privacy, I can guarantee if the government read everything everyone wrote/texted/read and recorded their every move, there would be less crime.
- menus 3y agoGreat to know that. I'll let the parents of Uvalde know how surveillance reduced crime on the 1 year anniversary of the school shooting. Surveillance does not reduce crime, tending to people's basics needs so that they don't need to commit crimes reduces crimes.
- xp84 3y agoIs a subpoena of 5 specific users' data, presumably with the purpose of getting evidence about things that already happened, the same as 'surveillance'? > the government read everything everyone wrote/texted/read is this really a relevant analogy for this? And yes, I've heard of the mass surveillance via telco that we did find out (through Snowden) was happening, and do think it seriously crossed the line. I'm just wondering if this kind of case at issue has anything in common with that malfeasance at all. Is it your belief that they lacked any probable cause and are actually trying to persecute those 5 people for some reason? Rather than try to argue against a position I'm not fully understanding, I'd like to hear how you think police should solve crimes with a significant "cyber" component.
- itake 3y agoI can't tell if this is sarcastic. While they are transparent the events happened, they are not transparent about which packages and what authors are being flagged, which is unfortunate.
- thih9 3y agoIs it possible that they can't publish that? Perhaps even not allowed to say that they can't publish that?
- einpoklum 3y ago> While they are transparent the events happened Considering they are admitting they will always obey government commands, including regarding non-disclosure of actions to affected users, it is prudent to assume they are, in fact, not transparent about events; only about those events which the government has let them tell you about. Other events (e.g. National Security Letters) may or may not have occurred.